GHSA-6jq2-789q-fff2
HIGHCVE-2018-11761In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
- Affected
- >= 0.1, < 1.19.1
- Fixed in
- 1.19.1
- Published
- 2018-10-17
- Source
- github